Regras de saída no Windows Server (Firewall — Parte 2)
Bloquear ou restringir tráfego de saída: política padrão, regras Outbound, whitelist e diagnóstico.
A Parte 1 cobriu entrada. Esta é sobre saída. Por defeito o Windows Server permite tudo a sair — cómodo mas arriscado.
Vídeo: Configura a tua primeira firewall — Parte 2/2 — YouTube
1. Política por defeito
wf.msc > Windows Defender Firewall Properties. Outbound = Allow por defeito. Mudar para Block ⇒ whitelist obrigatória.
2. Regra Outbound de bloqueio
Outbound Rules > New Rule… > Port > TCP 25 > Block. Ex.: bloquear SMTP de saída.
3. PowerShell — bloquear
New-NetFirewallRule -DisplayName "Block SMTP out" -Direction Outbound -Protocol TCP -RemotePort 25 -Action Block
Para IP: -RemoteAddress 198.51.100.42 -Action Block.
4. Por programa
-Program "C:\App\update.exe" -RemoteAddress 203.0.113.10 -Action Allow.
5. Whitelist (default-deny)
- Allow DNS 53, NTP 123, HTTPS 443, HTTP 80 se necessário.
- Allow por programa.
- Outbound default = Block.
- Reiniciar e validar.
6. Diagnóstico
Test-NetConnection www.fusiora.com -Port 443Get-NetFirewallRule -Direction OutboundSet-NetFirewallProfile -LogBlocked Truepktmon start -c+pktmon format
7. Erros comuns
- Bloquear DNS → sistema parte.
- Windows Update precisa *.windowsupdate.com 443.
- Ativação: KMS TCP 1688.
- Agente monitorização: Allow por programa.
Política de saída limita estragos em compromisso. Combina com Parte 1 e firewall do painel Fusiora.
Este artigo foi útil?
Seja o primeiro a avaliar